From SBOM to Submission: Operationalizing CRA Vulnerability Handling
The September 11, 2026 CRA deadline is approaching. Join Finite State and ISMG to learn the practical steps manufacturers should take now to build a risk-based vulnerability handling process, prioritize real exposure, and maintain the evidence needed to support ongoing CRA compliance.
From SBOM to Submission: Operationalizing CRA Vulnerability Handling
The September 11 CRA Deadline Is Approaching. Are You Ready?
The EU Cyber Resilience Act (CRA) reporting requirements take effect on September 11, 2026. Join Finite State and ISMG to learn the practical steps manufacturers should take now to build a documented, risk-based vulnerability handling process that supports ongoing compliance.
In this webinar, you'll learn how to prioritize real exposure using binary-derived SBOMs, exploit intelligence, reachability analysis, and VEX, while creating the evidence needed to support Annex VII documentation and Article 14 reporting obligations.
What You'll Learn
- What CRA expects from vulnerability handling programs
- How to prioritize vulnerabilities using reachability, EPSS, and CISA KEV
- Best practices for maintaining SBOM and VEX documentation
- How to build audit-ready evidence for ongoing compliance
Who Should Attend
- Product Security Leaders
- PSIRT Teams
- Security Architects
- Compliance & Regulatory Professionals
- Engineering Leaders responsible for connected products
Watch the Recording
Watch the recording now to learn how to prepare for the September 11 CRA deadline.
Speakers

Larry Pesce
VP of Services
Finite State

Joshua Marpet
Sr. Product Security Consultant
Finite State